HUMAN RISK INTELLIGENCE
Part of the Citadel Cyber Defense Platform · Brindwell & Partners

Your firewalls are perfect. Your people are not

80% of breaches begin with a human decision — a click, a trust, a shared password, a moment of distraction. AI-generated phishing now outperforms elite human red teams. Deepfake voices clone your CEO in seconds. Vishing attacks bypass MFA through the helpdesk. Citadel Phantom transforms your workforce from the weakest link in your security chain into an active, intelligent, and resilient human defense layer.

⚠ PHANTOM SIMULATION
AI-GENERATED
Urgent: Your password expires in 2 hours

Hi Sarah, your corporate password expires today at 5:00 PM EST. To avoid being locked out of all systems including email, VPN, and SharePoint, please update your password immediately using the secure link below. This is an automated notification from IT Security.

⚡ PHANTOM ANALYSIS: AI-generated phishing simulation. OSINT-personalized using target's name, role, and company systems. Domain spoofs corporate branding. Urgency trigger: "2 hours." 73% of untrained employees click. 4% click after Phantom training.
80%
Of breaches begin with a human
55%
AI outperforms human phishers by 55%
73→4%
Click rate reduction with training
50%
Fewer phishing incidents in 12 months
The Human Layer

You spent millions on firewalls, EDR, SIEM, and zero trust architecture. Then an employee clicked a link in a phishing email and the attacker walked through the front door with valid credentials. The most sophisticated technical defenses in the world fail when someone trusts the wrong email, answers the wrong phone call, or plugs in the wrong USB drive. AI has made this exponentially worse: AI-generated phishing now outperforms elite human red teams by 55%, deepfake voices can clone any executive from 10 seconds of audio, and multi-channel social engineering attacks coordinate email, phone, SMS, and video to create scenarios that even security professionals struggle to detect.

Phantom does not deliver annual compliance training that employees click through while checking their phones. It builds genuine human resilience through AI-powered adaptive simulations that mirror the exact attacks targeting your organization, personalized to each employee's role, digital footprint, and behavioral vulnerability profile. It measures human risk with the same precision you apply to technical risk. And it transforms every employee from a potential victim into an active sensor in your security infrastructure — trained to recognize, report, and resist social engineering at every level of sophistication.

Defense Engines

Eight engines. From vulnerability to resilience.

Phantom measures, trains, simulates, and scores human risk with the precision your board demands.

ENGINE 01
AI Phishing Simulation & Adaptive Training
AI generates hyper-realistic phishing simulations personalized to each employee's role, OSINT exposure, and behavioral profile — adapting difficulty as resilience improves.
AI phishing simulations reduce click rates from 20% to 3.5% in 18 months

Static phishing templates are obsolete — because real attackers don't use templates. Phantom's AI phishing engine generates unique, contextually personalized simulations for every employee, every time. The system uses the same OSINT data real attackers exploit — LinkedIn profiles, public social media, corporate website bios, conference appearances — to craft phishing emails that reference the employee's actual role, projects, colleagues, and interests. Difficulty adapts automatically: employees who consistently detect simulations receive increasingly sophisticated attacks, while those who click receive targeted micro-training and easier simulations to build confidence before escalating complexity.

Capabilities
20→3.5%
Click rate reduction over 18 months of adaptive training
OSINT
Simulations personalized using same intelligence real attackers use
ENGINE 02
Vishing & Deepfake Voice Defense
AI voice phishing simulations using cloned executive voices — training employees to resist the social engineering attacks that bypass MFA and technical controls entirely.
46% of organizations have faced deepfake attacks — most employees cannot detect them

Voice phishing is the fastest-growing social engineering vector — and the hardest to defend against with technical controls. When an employee receives a phone call that sounds exactly like their CEO asking them to urgently wire $200,000, no firewall can help. Phantom's vishing engine generates AI-cloned voice simulations using authorized voice samples from executives, IT staff, and other high-value impersonation targets. Employees learn to verify through established channels, recognize urgency manipulation, and resist authority pressure — regardless of how convincing the voice sounds. Deepfake video call simulations train employees to detect the subtle artifacts in AI-generated video conferencing.

Capabilities
Voice
AI-cloned executive voice simulations for vishing training
Video
Deepfake video call simulation for conference-based social engineering
ENGINE 03
OSINT Exposure & Digital Footprint
Scans your employees' digital footprint across 400+ data sources — identifying the personal information that attackers weaponize for targeted social engineering.
Employees with high OSINT exposure are 4× more likely to be targeted

Before an attacker sends a phishing email, they research the target — LinkedIn profile, social media, corporate website bio, conference presentations, breach databases, public records. Phantom's OSINT engine performs the same reconnaissance on every employee in your organization, scoring their digital exposure across 400+ data sources. The result is an individualized vulnerability score that identifies which employees are most exposed and what specific information attackers can exploit. The system recommends specific actions to reduce exposure — privacy setting changes, content removal requests, credential resets — and prioritizes training for the most vulnerable individuals.

Capabilities
400+
Data sources scanned per employee for OSINT exposure
Score
Individualized vulnerability score with remediation recommendations
ENGINE 04
Human Risk Scoring & Analytics
Quantifies human risk at individual, team, department, and organizational levels — with the same precision you apply to technical vulnerability management.
Transforms subjective "awareness" into measurable, boardroom-ready risk metrics

You cannot manage what you cannot measure. Phantom quantifies human risk with the same rigor applied to technical vulnerability scanning: individual risk scores based on simulation performance, OSINT exposure, training completion, phishing report rates, and behavioral trends. Aggregated views show risk by department, location, job function, and seniority level — revealing that the finance team clicks phishing at 3× the engineering rate, or that C-suite executives are the most vulnerable population despite the lowest training completion. Board-ready dashboards present human risk alongside technical risk for a unified organizational risk posture.

Capabilities
Score
Individual, team, department, and org-level human risk scores
Board
Executive-ready dashboards integrating human and technical risk
ENGINE 05
Multi-Channel Attack Simulation
Simulates coordinated social engineering across email, voice, SMS, messaging apps, and video — because real attackers don't limit themselves to one channel.
Multi-channel campaigns are 3× more effective than single-channel phishing

Modern social engineering attacks are multi-channel: an email establishes context, a phone call creates urgency, an SMS delivers the malicious link, and a follow-up Teams message provides false confirmation. Training against email-only phishing leaves employees vulnerable to the coordinated campaigns that sophisticated attackers actually deploy. Phantom simulates multi-channel attack scenarios: a phishing email followed by a vishing call from a cloned IT helpdesk voice asking the employee to "verify" by clicking the link, or an SMS from a spoofed executive phone number directing the employee to a fake approval portal. These orchestrated simulations build resistance to the attacks that single-channel training cannot address.

Capabilities
5
Channels simulated: email, voice, SMS, messaging, video
Multi
Coordinated multi-step campaigns mirroring real attacker behavior
ENGINE 06
Security Culture Measurement
Measures organizational security culture beyond click rates — reporting behavior, peer influence, policy compliance, and security sentiment.
Organizations with strong security culture experience 70% fewer successful social engineering attacks

Click rates measure one behavior. Security culture measures the environment that produces all behaviors. Phantom's culture measurement engine assesses seven dimensions of organizational security culture: reporting behavior (do employees report suspicious emails or delete them?), peer influence (do teams discuss security or ignore it?), management support (do leaders model secure behavior?), policy knowledge (do employees understand security policies?), security sentiment (do employees view security as an enabler or an obstacle?), accountability (do employees take personal responsibility?), and communication (does the security team communicate effectively?). Culture scores predict phishing susceptibility more accurately than training completion rates alone.

Capabilities
7
Security culture dimensions measured and tracked over time
70%
Fewer social engineering incidents in organizations with strong culture scores
ENGINE 07
Insider Threat Behavioral Intelligence
Detects behavioral indicators of insider threat — disgruntlement, policy violations, data hoarding, and pre-departure activity patterns.
Behavioral indicators precede 74% of insider threat incidents by 30+ days

Not all human risk comes from outside. Insider threats — whether malicious or negligent — are responsible for 25% of breaches and often the most damaging because insiders already have access. Phantom's insider threat engine monitors behavioral indicators that precede insider incidents: increased data downloads, after-hours access to sensitive systems, email forwarding to personal accounts, USB usage spikes, access to files outside normal role scope, and patterns associated with pre-departure data theft. The system does not surveil employees — it detects behavioral deviations from established baselines that warrant investigation, respecting privacy while protecting the organization.

Capabilities
30d
Average lead time for behavioral indicators before insider incidents
Privacy
Baseline-deviation detection, not surveillance — respects employee privacy
ENGINE 08
Compliance & Regulatory Automation
Automated compliance training for HIPAA, PCI-DSS, SOX, GDPR, NIST, and industry-specific requirements — with tracking, certification, and audit documentation.
Automated compliance lifecycle eliminates manual training administration

Compliance training is table stakes — but it should not be the entire program. Phantom automates the compliance training lifecycle: auto-enrolling new hires, assigning role-based training modules (HIPAA for healthcare workers, PCI-DSS for payment handlers, SOX for financial staff), tracking completion with automated reminders, generating compliance certificates, and producing audit-ready documentation. The system supports 25+ regulatory frameworks across 40+ languages, with content updated continuously as regulations evolve. By automating compliance, Phantom frees the security team to focus on the adaptive, simulation-based training that actually changes behavior.

Capabilities
25+
Regulatory frameworks supported with auto-updating content
40+
Languages for global workforce training
Deployment Results
Global Financial Institution — 48,000 Employees

Phishing click rate reduced from 22% to 3.1% in 14 months

Phantom replaced a legacy annual training program with AI-powered adaptive simulations across email, voice, and SMS. OSINT scanning revealed that 2,400 employees had credentials in public breach databases. Personalized simulations were calibrated to each employee's role, digital exposure, and behavioral profile. Click rates dropped from 22% to 3.1%. Report rates increased from 8% to 64%. Three BEC attempts were detected and reported by trained employees who recognized the social engineering patterns — preventing $4.2M in combined wire fraud. The CISO reported to the board that human risk was now quantified, tracked, and improving measurably for the first time.
22→3.1%
Click rate
8→64%
Report rate
$4.2M
Fraud prevented
Technology Company — Deepfake CEO Fraud Prevention

Vishing training prevented $1.8M deepfake voice fraud attempt

A CFO received a phone call that sounded exactly like the company's CEO, urgently requesting an emergency wire transfer of $1.8M to close a confidential acquisition. The voice was an AI deepfake generated from a conference keynote recording. Because the CFO had completed Phantom's vishing training — including simulations using AI-cloned executive voices — she recognized the urgency pattern, requested verification through the established callback procedure, and reported the attempt. The attack was neutralized without financial loss. Post-incident analysis confirmed the voice clone was generated from a 90-second YouTube clip of the CEO's public remarks.
$1.8M
Fraud prevented
90sec
Audio used for clone
Trained
CFO recognized pattern
Healthcare System — Security Culture Transformation

Security culture score improved from 42 to 78 — phishing incidents dropped 67%

A 14,000-employee healthcare system deployed Phantom to transform a compliance-driven security training program into a behavior-driven security culture. Baseline culture measurement scored 42/100, with nursing staff at 31 and physicians at 28. Adaptive simulations, gamified micro-training, department-level leaderboards, and executive engagement campaigns raised the culture score to 78 within 18 months. Actual phishing-related incidents dropped 67%. Phishing report rates increased 8× — meaning employees were actively detecting and reporting threats rather than ignoring or falling for them. The program was cited by the health system's cyber insurer as grounds for a premium reduction.
42→78
Culture score
67%
Fewer incidents
Report rate increase
Voices

The deepfake vishing simulation terrified me — in exactly the right way. I received a phone call that sounded exactly like my CEO, asking me to approve an emergency payment. Everything about the call was perfect — his voice, his speech patterns, even the background noise from the airport lounge he's often in. But I had been through Phantom's vishing training. I knew to verify. I called the CEO's mobile directly. He was in a meeting. He had made no such call. That training saved us $1.8 million. And the deepfake was generated from a 90-second conference clip on YouTube. Ninety seconds of audio. That is all it takes now.

Chief Financial Officer
Enterprise Finance
Series D Technology Company

The OSINT exposure report was a wake-up call for our entire executive team. We discovered that our CEO's home address, personal email, children's school, and vacation patterns were all publicly accessible through social media, property records, and travel check-ins. Our COO's credentials from a 2019 breach were still being sold on a dark web forum. Our VP of Engineering had posted his work calendar publicly on a scheduling tool. We spent six years building firewalls. We never thought to Google ourselves. Phantom showed us what the adversary already knew about us.

Chief Information Security Officer
Information Security & Privacy
Fortune 500 Manufacturing Company

Our board used to ask "what's our click rate?" Now they ask "what's our human risk score?" That shift — from a single metric to a comprehensive, quantified understanding of human risk — is the most important change Phantom delivered. We can now show the board that our finance team is at high risk for BEC, that our engineering team has the lowest phishing susceptibility but the highest insider threat indicators, and that our security culture score improved from 42 to 78 in 18 months. Human risk is no longer a feeling. It is a number. And it is going down.

VP of Cybersecurity
Enterprise Security Operations
14,000-Employee Healthcare System
73→4%
Click rate reduction
50%
Fewer phishing incidents
67%
Security culture improvement
$4.2M
Fraud prevented
Fortify Your People

The human is not the weakest link. The untrained human is.

Deploy Phantom to measure, train, and transform your workforce from a vulnerability into a defense layer.

Includes complimentary OSINT exposure scan for your executive team: phantom@brindwell.com